Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1409af1d by Salvatore Bonaccorso at 2022-02-22T07:18:27+01:00
Add three mruby issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -975,11 +975,17 @@ CVE-2022-0634
 CVE-2022-0633 (The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium 
before ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-0632 (NULL Pointer Dereference in Homebrew mruby prior to 3.2. ...)
-       TODO: check
+       - mruby <not-affected> (Vulnerable code introduced later)
+       NOTE: https://huntr.dev/bounties/3e5bb8f6-30fd-4553-86dd-761e9459ce1b
+       NOTE: 
https://github.com/mruby/mruby/commit/44f591aa8f7091e6ca6cb418e428ae6d4ceaf77d
 CVE-2022-0631 (Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. ...)
-       TODO: check
+       - mruby <not-affected> (Vulnerable code introduced later)
+       NOTE: https://huntr.dev/bounties/9bdc49ca-6697-4adc-a785-081e1961bf40
+       NOTE: 
https://github.com/mruby/mruby/commit/47068ae07a5fa3aa9a1879cdfe98a9ce0f339299
 CVE-2022-0630 (Out-of-bounds Read in Homebrew mruby prior to 3.2. ...)
-       TODO: check
+       - mruby <not-affected> (Vulnerable code introduced later)
+       NOTE: https://huntr.dev/bounties/f7cdd680-1a7f-4992-b4b8-44b5e4ba3e32
+       NOTE: 
https://github.com/mruby/mruby/commit/ff3a5ebed6ffbe3e70481531cfb969b497aa73ad
 CVE-2022-0629 (Stack-based Buffer Overflow in GitHub repository vim/vim prior 
to 8.2. ...)
        - vim <unfixed>
        [bullseye] - vim <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1409af1d29193ab00587b4a26bc8f3c8dfea7476

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1409af1d29193ab00587b4a26bc8f3c8dfea7476
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to